https://cert-portal.siemens.com/productcert/html/ssa-486936.html
https://support.industry.siemens.com/cs/ww/en/view/109995159/
https://www.cisa.gov/news-events/ics-advisories/icsa-25-289-07
Severity: Critical
ID: 503756
Version: 1.3
Type: remote
Family: Tenable.ot
Published: 10/27/2025
Updated: 10/28/2025
Supported Sensors: Tenable OT Security
Risk Factor: Medium
Score: 6.7
Risk Factor: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:/o:siemens:siplus_et_200sp_cp_1543sp-1_isec_tx_rail_firmware, cpe:/o:siemens:simatic_cp_1542sp-1_firmware:2.4.24, cpe:/o:siemens:simatic_cp_1542sp-1_irc_firmware:2.4.24, cpe:/o:siemens:siplus_et_200sp_cp_1543sp-1_isec_firmware:2.4.24, cpe:/o:siemens:siplus_et_200sp_cp_1542sp-1_irc_tx_rail_firmware:2.4.24, cpe:/o:siemens:simatic_cp_1543sp-1_firmware:2.4.24
Required KB Items: Tenable.ot/Siemens
Exploit Ease: No known exploits are available
Patch Publication Date: 10/14/2025
Vulnerability Publication Date: 10/14/2025
CVE: CVE-2025-40771
CWE: 306